URLhaus Database

You are currently viewing the URLhaus database entry for https://africadamx.com/wp-admin/l/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:694766
URL: https://africadamx.com/wp-admin/l/
URL Status:Offline
Host: africadamx.com
Date added:2020-10-14 22:58:06 UTC
Last online:2020-10-15 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 23:00:16 UTC to abuse{at}ovh[dot]net)
Takedown time:8 hours, 41 minutes Good (down since 2020-10-15 07:42:07 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-158U9OnMB2dPEL.exeexe 6018cb14a8151fec12b259e5f20491b67e39698ea36e5e51dfa49c7902c32e8en/a Heodo
2020-10-153XhyP3.exeexe a13c7fe862224f9bf2a8c3d7f0fe768774da94aaf5692c4dd97960af8add945bn/a Heodo
2020-10-15mNdUxm2DNk2Nw7lR9E.exeexe 6461291aa6998dae767d777e63e5d95db610fb2effc34b783082ae91b21db41en/a Heodo
2020-10-152gTSNAYXmGUHp8OYNKv.exeexe 345e7ecd104f8fb4106756fa82460a55d5ce809c02230a015857e3e019d8c440Virustotal results 18.31% Heodo
2020-10-15NwLg.exeexe 830f361d29657cf9149887f45316ab39cac675aa600e9f167c411b8521a5af35n/a Heodo
2020-10-15EgYQbtes.exeexe 605bc057ecf67a0b877ed144570bab51bb73778012df224f41900b09a3245b9fn/a Heodo
2020-10-15z6T5mYvB.exeexe 3249ceeecabdbc3f8929395ea8f960a25cf1f6d42910737d6f18776494c4aa9fn/a Heodo
2020-10-152ZIB91mafAX0kO.exeexe 868a19a30d94bc419b6e04fc08c1b38d2825974d9406f6a8b792b65761eb1667n/a Heodo
2020-10-15oW1xhzn5loo6.exeexe a9bd71c3462b58e6ec8247fbc3225023ac64f67ad0707c33350fd0f13def3601n/a Heodo
2020-10-15JWQXwGoMpmY5MUNR3Qab.exeexe 41447294f18e99fe5182c4a624325f6339e4412fc7785e6283d543b40fb5fc99n/a Heodo
2020-10-15ZhuC6bVGEnLZG9oVN.exeexe 205dafbe019d4388b8a396c340347882f5970abe2510eed819e878cd287de316n/a Heodo
2020-10-15k6LAB4uw.exeexe f3b844c725c00092bce675bbe20f39de681f6fd7fd89660aa558d43e33bdc1b9n/a Heodo
2020-10-15pddSDsB.exeexe 02670d8c852518ebaf3d0ceb74577c858420873431239fd6532c563044ce92ecn/a Heodo
2020-10-15FHqJgSx6Yqv8R.exeexe 0846174a2e27d1d080bcaa2b656f52307c898eeb6a2d9dbc5e05d8918c9379a7n/a Heodo
2020-10-15XuEY6KVIyooM.exeexe 253458ad6e00b29e2f81cddfc829a8246ae45aefb9e7d91b5bfaf7527badf893n/a Heodo
2020-10-15PUiiEJZI.exeexe 153b48ad82d39d73817eee5153ad9a0426c3846efe5d839ce0e1270bb621ed79Virustotal results 18.57% Heodo
2020-10-15GKnbh.exeexe 8fc723aceaef40dc9e82bab7c2a46486b117ca9844f2fde68365197c334c6215Virustotal results 16.90% Heodo
2020-10-15wufkL0YBw0e.exeexe 1a5fa0edef8f88ce62abc5188495a12c2099b5183efdb7846b9e32e4d9691f77n/a Heodo
2020-10-15CXBCbX.exeexe 471a9ae074d84ffc16eecf5a6a263b55224c903e10ce950444129af65de7cbc4n/aHeodo
2020-10-14zpeoU0dfnJ.exeexe 1086c9afe4839aee5becd0b062c5aa2edf2db5c6a2df136484443f3d0e4fafban/a Heodo
2020-10-14t3qEik.exeexe 4f04b24ef6cb96a7ae3266be6fc88fe82362a3405c55715e15c927854d1e6241n/a Heodo
2020-10-14rF.exeexe cb7c217a6c4f44a73c1af71137693af30299e80330835082ae6c1e99c61e4e24n/a Heodo
2020-10-14KAuoRT.exeexe 6fbf7f8a2a079736658cb8c31de9a9507fba7afd66c1bc371b279226828ec0a8n/a Heodo